Cybersecurity

Cybersecurity
Pentagon Records Agency Breach Exposes Data on 3 Million
A breach of the Pentagon's Defense Manpower Data Center exposed unencrypted personal data on 3 million people, with notice sent months after discovery.
Cybersecurity
France Tax Agency Breached Seven Weeks via Stolen Passwords
An attacker used infostealer-harvested passwords to breach France's DGFIP tax portals for seven weeks, exposing millions of taxpayer and business records.
CVE Vulnerability Alerts
Citrix NetScaler Zero-Days Deployed WHIPSHOT, SLAPSHOT
Attackers exploited two Citrix NetScaler zero-days to plant custom WHIPSHOT and SLAPSHOT malware, hitting government, financial, and legal-sector networks.
Cybersecurity
FBI Tells ShinyHunters Members to Turn Themselves In
The FBI publicly urged remaining ShinyHunters members to surrender after Dutch police arrested an alleged leader in Amsterdam and found plans for murders.
Cybersecurity
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
Microsoft says Russian state-backed group Star Blizzard used fake event invitations to install a Windows backdoor at more than 100 Ukraine-linked organizations.
Cybersecurity
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
Academics disclosed a Spectre-v2 variant called BTR that bypasses existing mitigations and recovers Linux root password hashes on Intel systems in minutes.
Application Security
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
An autonomous AI agent exploited a vulnerability to breach Dutch nonprofit DIVD on its own, leaving extensive forensic evidence of its intrusion attempt.
Application Security
OpenAI Discloses Self-Replicating Worm-Style Prompt Injection
OpenAI disclosed that GPT models can be manipulated into self-replicating prompt injections that spread like a worm across connected tools and channels.
Cybersecurity
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
Threat actors use sponsored Google search ads for fake ChatGPT tools to run ClickFix attacks that trick victims into installing remote access trojan malware.
Application Security
101 Malicious npm Packages Add Developers to WhatsApp Groups
OX Security found 101 malicious npm packages in a campaign called PhantomSub that add developers to WhatsApp groups without consent after installation.